Description:
Verifies if a Block Legacy Authentication protocol is applied. Augmentt will locate protocols blocking Legacy Authentication Clients and extrapolate the users of the conditional access policy to determine which users are successfully blocked.
The protocols can be applied via one of the following options:
Organizations with Basic licensing: blocking via Security Defaults.
Organizations with Microsoft Entra ID P1 or P2 licenses: blocking via Conditional Access Policy.
Why:
Blocking legacy authentication makes it harder for attackers to gain access. Office 2013 client apps support legacy authentication by default. Legacy means that they support either Microsoft Online Sign-in Assistant or basic authentication. In order for these clients to use modern authentication features, the Windows client has to have registry keys set.
Status detail shown in Augmentt: You have N of M users that have legacy authentication blocked.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Identity
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft Secure Score control BlockLegacyAuthentication.
Remediation in Augmentt: Guided remediation steps (Instructions tab); Conditional Access Policy manager
Compliance Frameworks:
CISA SCuBA — MS.AAD.1.1
NIST CSF 2.0 — PR.AA-02, PR.AA-01
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.2.2.3
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.2.2.3
HIPAA Security Rule — 164.312(d), 164.312(a)(1)
CMMC Level 1 — AC.L1-b.1.i, IA.L1-b.1.vi
CMMC Level 2 — IA.L2-3.5.2, IA.L2-3.5.3
Microsoft documentation:
